Forum Discussion

f51's avatar
f51
Icon for Cirrostratus rankCirrostratus
Jul 07, 2017

Internal VIP to Internal VIP

I am trying to point internal VIP to Internal VIP One VIP on port 443 and other VIP on port 5001. I am using VIP on port 443 as gateway for external application. From the external VIP to it has to reach Internal VIp to another internal VIP.

 

Is that possible ?

 

If I am wrong please suggest me ?

 

4 Replies

  • P_K's avatar
    P_K
    Icon for Altostratus rankAltostratus

    On what basis you want to use VIP:5001 ?? like url, clientIP etc

     

  • f51's avatar
    f51
    Icon for Cirrostratus rankCirrostratus

    Thank you PK for quick response

     

    PublicIP-->dmz-->internala --> Internalb

     

    Dmz and internala as gateway for publicIP to reach internalb

     

  • I'm not sure you want an actual internal virtual server:

     

    https://support.f5.com/csp/article/K15819

     

    It's pretty easy to target another virtual server on a different BigIP, but there are definite limitations when both Virtual Servers live on the same BigIP. You would need to use an iRule to redirect traffic to the second virtual server:

     

    https://support.f5.com/csp/article/K10379

     

    It might be better to have a virtual server listening on 443 and simply configure your pool members on port 5001 and go directly to the back end servers. As the BigIP is a full proxy it will simply initiate the back end connections on the new port. I can think of very few instances where you would actually need to have the second virtual server.

     

  • f51's avatar
    f51
    Icon for Cirrostratus rankCirrostratus

    Thank you for your help PK and Chris Grant. In my scenario PublicIP-->dmz-->internala --> Internalb We are using Dmz and internala as gateway for publicIP to reach internalb Application team, they are making policy to call internalb VIP name.

     

    So that they can use internalb servers.